Booking.com
2.3M guest records compromised in phishing campaign targeting hotels
2026 continues the year-over-year growth trend in confirmed disclosures. The list below updates as new breaches are reported by Verizon DBIR partners and major security news outlets.
2.3M guest records compromised in phishing campaign targeting hotels
1.5M customer records compromised in second incident
560K manufacturing and IoT device records exposed
2.1M customer records from Caribbean and Central American operations exposed
78K health card records compromised
450K member records compromised
280K resident records compromised
780K patient records exposed in data exfiltration
17.5M account records posted to BreachForums
560K corporate client records stolen
420K resident records stolen in targeted attack
750K Canadian investors exposed — SINs, income, account statements via phishing attack
950K rewards member records exposed via API vulnerability in mobile order-ahead system
3.6M beneficiary records exposed via compromised contractor with access to benefits system
1.3M patient records exposed via zero-day in medical imaging PACS system
2.1M patient records accessed via compromised third-party integration at EHR giant
120K workspace records exposed via OAuth misconfiguration
2.1M patient records compromised in ransomware incident
1.4M client consulting records from 23 countries exposed via LockBit affiliate intrusion
190K employee and project records from Canadian engineering firm compromised
Microsoft Office PowerPoint Code Injection Vulnerability — Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineT
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability — Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code ex
Engineering documents and employee data stolen via Accellion FTA exploit — posted on CL0P leak site
20,363 records exposed — Ages, Astrological signs, Bios, Device information and 18 more